CTI-CMM version 1.1 is here!
It's here!
Introducing the Cyber Threat Intelligence Capability Maturity Model (CTI-CMM)
CTI-CMM version 1.1 is here!
Introducing the Cyber Threat Intelligence Capability Maturity Model (CTI-CMM)
The CTI-CMM is a community-driven framework designed to provide CTI programs with a roadmap to improve organizational reach through internal stakeholder support. The cornerstone of an effective CTI program—and key to most program's maturation—is rooted in the ability to understand and service internal customer needs.
As a service-driven function, CTI programs demonstrate value by supporting cybersecurity and risk management outcomes. CTI teams develop products that provide timely and relevant insights about the cyber threat landscape, cyber threat actors, their capabilities, and motivations to inform risk exposure, planning, and cyber defense actions.
The CTI-CMM version 1.0 consists of 11 overarching domains, aligning to defined practices for stakeholder types found within most organizations. Through a series of common stakeholder use cases, the CTI-CMM offers prescriptive practices and measures to define how a CTI team can mature its level of support to each stakeholder type.
In CTI-CMM version 1.1, we released a Beta assessment tool, built as an Excel spreadsheet, for CTI programs to benchmark their current level of support to stakeholder functions.
The success of your CTI program relies on its ability to bring value to your stakeholders, the people who make decisions and take actions to protect your organization. This CTI-CMM focuses on building capabilities to help them solve problems and create lasting value.
Unlocking the full potential of your CTI program requires alignment with the capabilities of each stakeholder it supports. This CTI-CMM bridges the maturity gap by mapping specific CTI practices to the maturity level expectations of each stakeholders it supports.
The CTI-CMM was developed collaboratively by a volunteer group of industry experts representing multiple sectors, geographies, backgrounds, and experiences. Collectively, we have built programs and led teams across tactical and strategic levels in both the vendor and consumer spaces within the public and private sectors.
Get your hands on the CTI-CMM and start growing your program. For historical archiving, we are including a list of past versions, but recommend using the most recent version, 1.1, as content has changed. Please consult our CTI-CMM change log for specifics.
Want to give feedback? Please use this Google Form to tell us what you think!